← Back to Baseline

MB-R328

HUMAN VERIFICATION REQUIRED ASVS 10.4.16 Strong confidential-client authentication (when oauth_oidc is used)

MB-C18 ASVS Level 3 Human Assurance High

The client is confidential and the authorization server requires the use of strong client authentication methods (based on public-key cryptography and resistant to replay attacks), such as mutual TLS ( 'tls\_client\_auth', 'self\_signed\_tls\_client\_auth') or private key JWT ( 'private\_key\_jwt').